There's been a ton of talk about the role of humans in code review, and when and how humans should be signing off on changes.
I believe that, long-term, humans have no role in routinely reviewing code.
Great deep dive from the GitLab team on DPRK’s "Contagious Interview" and illicit IT worker campaign. This isn’t just a surface-level write-up. It shows how a platform can operationalize its own telemetry, extract high-signal intelligence, and convert that into concrete, actionable insights for the broader security community. Seriously impressive work. 👏
Blog: https://t.co/B9pPZwaiuv
If you want even more context, the Three Buddy Problem podcast did a great breakdown of the blog and unpacked the tradecraft, detection implications, and what this means for defenders. TBP is basically my go-to weekend running podcast, so it was extra cool to hear them dive into this and appreciate the shoutout me, guys. 🙇♂️
TBP Podcast: https://t.co/fFZyUxhFYz
@__paleologo@halvarflake Hamming indeed. Hammond’s book would have calculations of clarksons swear words per minute and speed estimates for the stig on roads.
🚨 Censys on #React2Shell (CVE-2025-55182): We observe ~2.15M exposed web services running Next.js or other RSC-based frameworks—mostly in the U.S. and China. Not all are vulnerable, but active exploitation is underway. Patch now.
👉 Full advisory: https://t.co/InIZwIyNM1
Very clever - with this approach I wonder if you’ll get the data from werfaultsecure.exe or if that will be frozen too?
Are the only detections around this device reporting, or collecting telemetry from multiple sources (eg osquery + agent + event logs)?
A new evasion technique known as "EDR-Freeze" has emerged, changing the way attackers neutralize endpoint security. Unlike traditional methods that attempt to crash or terminate security software (which often triggers alerts), EDR-Freeze suspends the security process entirely, rendering it "comatose" but technically alive. This attack is particularly dangerous because it operates entirely in user mode, meaning it does not require the attacker to bring a vulnerable driver (BYOVD) or exploit kernel-level flaws. Instead, it abuses legitimate Windows error reporting tools to freeze Endpoint Detection and Response (EDR) agents, creating a blind spot where malicious activity can occur undetected.
https://t.co/60aVeVHl2V
A new evasion technique known as "EDR-Freeze" has emerged, changing the way attackers neutralize endpoint security. Unlike traditional methods that attempt to crash or terminate security software (which often triggers alerts), EDR-Freeze suspends the security process entirely, rendering it "comatose" but technically alive. This attack is particularly dangerous because it operates entirely in user mode, meaning it does not require the attacker to bring a vulnerable driver (BYOVD) or exploit kernel-level flaws. Instead, it abuses legitimate Windows error reporting tools to freeze Endpoint Detection and Response (EDR) agents, creating a blind spot where malicious activity can occur undetected.
https://t.co/60aVeVHl2V
@cyb3rops are you aware of any (many?) folks using sigma and then expanding the language to cover more capabilities that are in their detection platforms? like sigma + an expansion pack?
Theres an interesting similarity between frontier AI model training and 0-day exploit development. You spend months in secret using custom techniques to explore emergent behaviors and properties, undocumented constraints and behaviors in a poorly understood system, all with no guarantees you’ll be successful. You’re on the lookout for leaks, operational security missteps, shifting baselines and requirements. And in the end some other team beats you to the finish line, and in a moment renders months of your work meaningless.
There is no moat other than hardware. Everything is proven to be fungible. Models, data, infrastructure, deep integrations, …
Apart from hardware, attracting the world’s best researchers and engineers is the other clear answer if you give them a productive environment.
@anton_chuvakin Kind of the flipside - there are also ppl who thrive managing (or performing generally) in those high-stress environments, who struggle in the fair weather environments. I think I saw this referred to in Eng terms as war-time vs peace-time.
@ImposeCost though caution: correlation != causation.
It would be super cool to see if you all could reproduce and/or see what the state of today is.
one draft of the preso: https://t.co/ZSvO8Y9ycN
@ImposeCost tl;dr - mid-2010s seems physical world actions and bot takedowns had the most impact, and often led to a rise in activity as the actors may have tried to re-capture market share - either after mules arrested or botnets taken down.
Very much agree with this perspective. AI/ML will become de rigueur in most tools, allowing for more time spent on custom analysis - the hard part and what we don’t want to repeat is generating 2012-2016s overwhelming false positive flood of UEBA alerts.
@HostileSpectrum Imo, because ML applications will be widely commercialized, outputs therefrom will effectively become *commoditized* (and quite "mid", as the kids say), which will then skyrocket the value of creative, artisanal, bench-made, human-generated content.